Techniques represent 'how' an adversary achieves a tactical goal by performing an action. For example, an adversary may dump credentials to achieve credential access.

Linked Issues

Issuelinks
Linktyp Issue
is related to Service Stop
is related to Modify Parameter
is related to Modify Controller Tasking
is related to Wireless Sniffing
is related to Loss of View
is related to Command Message
is related to Activate Firmware Update Mode
is related to Manipulation of Control
is related to Denial of Service
is related to System Binary Proxy Execution
is related to Role Identification
is related to Command-Line Interface
is related to Point & Tag Identification
is related to Device Restart/Shutdown
is related to User Execution
is related to Wireless Compromise
is related to Change Operating Mode
is related to Alarm Suppression
is related to Detect Operating Mode
is related to Loss of Protection
is related to Monitor Process State
is related to Scripting
is related to Remote System Information Discovery
is related to Program Upload
is related to Exploit Public-Facing Application
is related to Block Operational Technology Message
is related to Data from Information Repositories
is related to Transient Cyber Asset
is related to Siemens Project File Format
is related to Manipulate I/O Image
is related to Network Sniffing
is related to Rootkit
is related to Automated Collection
is related to Insecure Credentials
is related to Command Message
is related to Data Destruction
is related to Manipulation of View
is related to Data Historian Compromise
is related to Reporting Message
is related to Network Service Scanning
is related to Indicator Removal on Host
is related to I/O Image
is related to Serial COM
is related to Default Credentials
is related to Denial of View
is related to Program Append
is related to Execution through API
is related to Port Scan
is related to Supply Chain Compromise
is related to Serial Connection Enumeration
is related to Loss of Safety
is related to Ethernet
is related to Loss of Productivity and Revenue
is related to Spearphishing Attachment
is related to Multicast Discovery
is related to System Firmware
is related to Hardcoded Credentials
is related to Wi-Fi
is related to Location Identification
is related to Module Firmware
is related to Download All
is related to Autorun Image
is related to Drive-by Compromise
is related to Reporting Message
is related to Modify Firmware
is related to Damage to Property
is related to Exploitation of Remote Services
is related to External Remote Services
is related to Brute Force I/O
is related to Detect Program State
is related to Adversary-in-the-Middle
is related to Exploitation for Evasion
is related to Loss of Control
is related to Change Program State
is related to Hooking
is related to Control Device Identification
is related to Program Organization Units
is related to Graphical User Interface
is related to Rogue Master
is related to Native API
is related to Loss of Availability
is related to Theft of Operational Information
is related to Masquerading
is related to Program Download
is related to Replication Through Removable Media
is related to Broadcast Discovery
is related to Screen Capture
is related to Valid Accounts
is related to Exploitation for Privilege Escalation
is related to Remote System Discovery
is related to Engineering Workstation Compromise
is related to Connection Proxy
is related to Online Edit
is related to Standard Application Layer Protocol
is related to Modify Control Logic
is related to Unauthorized Message
is related to Remote Services
is related to I/O Module Discovery
is related to Denial of Control
is related to Modify Alarm Settings
is related to Commonly Used Port
is related to Project File Infection
is related to Network Connection Enumeration
is related to Lateral Tool Transfer
is related to Internet Accessible Device
is related to Data from Local System
is related to Change Credential
is related to Block Communications
is related to Modify Program
is related to Extra Window Memory Injection
is related to Scheduled Task
is related to Socket Filters
is related to Archive via Utility
is related to VNC
is related to Windows Management Instrumentation
is related to Exploitation for Defense Impairment
is related to Screen Capture
is related to Fileless Storage
is related to Boot or Logon Initialization Scripts
is related to Adversary-in-the-Middle
is related to System Owner/User Discovery
is related to Acquire Infrastructure
is related to Rundll32
is related to Container and Resource Discovery
is related to Serverless
is related to Standard Encoding
is related to Embedded Payloads
is related to Pluggable Authentication Modules
is related to Revert Cloud Instance
is related to Gather Victim Host Information
is related to Digital Certificates
is related to Keylogging
is related to File/Path Exclusions
is related to Linux and Mac Permissions
is related to Password Guessing
is related to PubPrn
is related to Purchase Technical Data
is related to OS Credential Dumping
is related to Shared Modules
is related to Data from Configuration Repository
is related to Disk Structure Wipe
is related to Direct Network Flood
is related to Path Interception by PATH Environment Variable
is related to Sharepoint
is related to Direct Volume Access
is related to Artificial Intelligence
is related to Modify Cloud Resource Hierarchy
is related to Email Hiding Rules
is related to External Defacement
is related to Encrypted/Encoded File
is related to IP Addresses
is related to OS Exhaustion Flood
is related to Rootkit
is related to PowerShell Profile
is related to JavaScript
is related to Modify or Spoof Tool UI
is related to DNS
is related to Lifecycle-Triggered Deletion
is related to Audio Capture
is related to Create or Modify System Process
is related to External Remote Services
is related to LC_LOAD_DYLIB Addition
is related to Steal Web Session Cookie
is related to Container Orchestration Job
is related to Domain Generation Algorithms
is related to Double File Extension
is related to Bypass User Account Control
is related to SMS Pumping
is related to Internet Connection Discovery
is related to Sudo and Sudo Caching
is related to Disable or Modify Windows Event Log
is related to Query Public AI Services
is related to Archive via Custom Method
is related to Modify Cloud Compute Infrastructure
is related to Network Devices
is related to Malvertising
is related to Permission Groups Discovery
is related to Email Collection
is related to Security Account Manager
is related to WHOIS
is related to System Firmware
is related to Search Victim-Owned Websites
is related to Cloud Groups
is related to Services Registry Permissions Weakness
is related to DNS/Passive DNS
is related to Application Exhaustion Flood
is related to Compromise Software Dependencies and Development Tools
is related to Digital Certificates
is related to DNS Server
is related to Disk Wipe
is related to DNS
is related to Cloud Instance Metadata API
is related to Securityd Memory
is related to Group Policy Discovery
is related to Bootkit
is related to Data from Removable Media
is related to Mavinject
is related to Local Data Staging
is related to Match Legitimate Resource Name or Location
is related to Digital Certificates
is related to Stored Data Manipulation
is related to Password Cracking
is related to Local Email Collection
is related to Keychain
is related to Boot or Logon Autostart Execution
is related to LSA Secrets
is related to Weaken Encryption
is related to SAML Tokens
is related to Masquerade File Type
is related to Service Stop
is related to Malware
is related to Device Driver Discovery
is related to Domain Account
is related to Active Setup
is related to Hide Artifacts
is related to Dynamic Data Exchange
is related to Malicious File
is related to Identify Business Tempo
is related to Disable or Modify Linux Audit System Log
is related to Publish/Subscribe Protocols
is related to Hardware
is related to Taint Shared Content
is related to Trust Modification
is related to Databases
is related to Symmetric Cryptography
is related to Local Account
is related to Social Media Accounts
is related to Browser Extensions
is related to TFTP Boot
is related to Windows Host Firewall
is related to Windows Service
is related to Fast Flux DNS
is related to System Checks
is related to Cron
is related to Domain Groups
is related to Vulnerabilities
is related to Spearphishing Link
is related to Application or System Exploitation
is related to Office Application Startup
is related to InstallUtil
is related to Spearphishing Link
is related to SSH
is related to Additional Cloud Roles
is related to Print Processors
is related to Spearphishing Attachment
is related to Stripped Payloads
is related to Component Object Model
is related to DLL
is related to Automated Collection
is related to Downgrade Attack
is related to Clipboard Data
is related to Proc Filesystem
is related to Botnet
is related to Password Managers
is related to Gatekeeper Bypass
is related to ESXi Administration Command
is related to Drive-by Target
is related to System Service Discovery
is related to Network Sniffing
is related to Code Signing
is related to Data from Cloud Storage
is related to Runtime Data Manipulation
is related to Credentials in Registry
is related to Network Share Discovery
is related to Peripheral Device Discovery
is related to Break Process Trees
is related to Network Topology
is related to Code Signing Certificates
is related to Windows Permissions
is related to Add-ins
is related to Disable or Modify Cloud Log
is related to Transport Agent
is related to System Information Discovery
is related to Application Layer Protocol
is related to AppDomainManager
is related to Remote Data Staging
is related to Additional Container Cluster Roles
is related to Scheduled Task/Job
is related to Msiexec
is related to Network Trust Dependencies
is related to Reflection Amplification
is related to Password Filter DLL
is related to Terminal Services DLL
is related to AppleScript
is related to Software Extensions
is related to Service Exhaustion Flood
is related to Compromise Hardware Supply Chain
is related to Native API
is related to Ccache Files
is related to Clear Network Connection History and Configurations
is related to AS-REP Roasting
is related to Virtual Private Server
is related to AutoHotKey & AutoIT
is related to Reduce Key Space
is related to Clear Command History
is related to Indirect Command Execution
is related to Replication Through Removable Media
is related to Data from Local System
is related to Deobfuscate/Decode Files or Information
is related to Outlook Rules
is related to Cloud Accounts
is related to Email Accounts
is related to Additional Local or Domain Groups
is related to Upload Malware
is related to Supply Chain Compromise
is related to Exploit Public-Facing Application
is related to Steal or Forge Kerberos Tickets
is related to Credentials from Password Stores
is related to Exfiltration Over Web Service
is related to Remote Access Tools
is related to Domains
is related to Archive via Library
is related to Thread Execution Hijacking
is related to Social Engineering
is related to Masquerading
is related to Application Shimming
is related to Unsecured Credentials
is related to Port Monitors
is related to Clear Mailbox Data
is related to Login Hook
is related to Content Injection
is related to Process Injection
is related to Exfiltration Over Webhook
is related to Traffic Signaling
is related to Direct Cloud VM Connections
is related to System Binary Proxy Execution
is related to Source
is related to Timestomp
is related to Evil Twin
is related to Reflective Code Loading
is related to Wi-Fi Discovery
is related to Mutual Exclusion
is related to Ignore Process Interrupts
is related to Escape to Host
is related to Backup Software Discovery
is related to Shortcut Modification
is related to Application Window Discovery
is related to Systemctl
is related to Email Account
is related to Hypervisor
is related to Time Based Checks
is related to CMSTP
is related to SSH Hijacking
is related to Scheduled Transfer
is related to SMB/Windows Admin Shares
is related to Implant Internal Image
is related to Protocol Tunneling
is related to Control Panel
is related to Network Address Translation Traversal
is related to Upload Tool
is related to Security Support Provider
is related to Overwrite Process Arguments
is related to Use Alternate Authentication Material
is related to Threat Intel Vendors
is related to Exfiltration Over Other Network Medium
is related to Network Device Configuration Dump
is related to Gather Victim Identity Information
is related to Archive Collected Data
is related to SIP and Trust Provider Hijacking
is related to Browser Session Hijacking
is related to Remote Services
is related to Mail Protocols
is related to Hybrid Identity
is related to Vulnerability Scanning
is related to Cloud API
is related to Search Open Technical Databases
is related to Electron Applications
is related to Rogue Domain Controller
is related to Code Signing Policy Modification
is related to Deploy Container
is related to Modify Registry
is related to Launch Daemon
is related to Cloud Infrastructure Discovery
is related to Credentials from Web Browsers
is related to Path Interception by Search Order Hijacking
is related to Defacement
is related to Unused/Unsupported Cloud Regions
is related to DHCP Spoofing
is related to Remote Service Session Hijacking
is related to Bind Mounts
is related to Binary Padding
is related to Web Shell
is related to Group Policy Modification
is related to Clear Linux or Mac System Logs
is related to Browser Information Discovery
is related to Private Keys
is related to Server
is related to Windows Remote Management
is related to Exfiltration Over Bluetooth
is related to Default Accounts
is related to Time Providers
is related to Trap
is related to Dynamic Linker Hijacking
is related to Local Account
is related to Search Threat Vendor Data
is related to Input Injection
is related to Communication Through Removable Media
is related to Email Accounts
is related to Name Resolution Poisoning and SMB Relay
is related to File and Directory Permissions Modification
is related to LSASS Memory
is related to IDE Extensions
is related to Active Scanning
is related to Junk Code Insertion
is related to Abuse Elevation Control Mechanism
is related to Create Process with Token
is related to Setuid and Setgid
is related to Winlogon Helper DLL
is related to Distributed Component Object Model
is related to Password Spraying
is related to External Proxy
is related to Web Portal Capture
is related to Email Addresses
is related to Spearphishing Voice
is related to Written Content
is related to Redundant Access
is related to Cached Domain Credentials
is related to SSH Authorized Keys
is related to Virtual Machine Discovery
is related to Network Security Appliances
is related to Image File Execution Options Injection
is related to Odbcconf
is related to Search Engines
is related to Business Relationships
is related to Temporary Elevated Cloud Access
is related to Video Capture
is related to Process Doppelgänging
is related to System Network Configuration Discovery
is related to Delete Cloud Instance
is related to Code Repositories
is related to Executable Installer File Permissions Weakness
is related to Accessibility Features
is related to Bandwidth Hijacking
is related to Account Discovery
is related to Proxy
is related to Command and Scripting Interpreter
is related to Malicious Library
is related to Clear Windows Event Logs
is related to Domain Account
is related to Extended Attributes
is related to Employee Names
is related to Poisoned Pipeline Execution
is related to Domain Trust Discovery
is related to Golden Ticket
is related to Component Object Model and Distributed COM
is related to Automated Exfiltration
is related to Client Configurations
is related to IDE Tunneling
is related to Right-to-Left Override
is related to Malware
is related to SVG Smuggling
is related to Component Firmware
is related to Indicator Removal
is related to Exfiltration Over Symmetric Encrypted Non-C2 Protocol
is related to Office Template Macros
is related to Virtual Private Server
is related to Confluence
is related to Pass the Ticket
is related to Container Administration Command
is related to File and Directory Discovery
is related to Dynamic Resolution
is related to Masquerade Task or Service
is related to Asynchronous Procedure Call
is related to Traffic Duplication
is related to Plist File Modification
is related to JamPlus
is related to AppCert DLLs
is related to Email Forwarding Rule
is related to Data Staged
is related to Steal or Forge Authentication Certificates
is related to Device Registration
is related to System Network Connections Discovery
is related to Compromise Infrastructure
is related to Mark-of-the-Web Bypass
is related to Disable Crypto Hardware
is related to Pre-OS Boot
is related to Scripting
is related to Build Image on Host
is related to Shared Webroot
is related to Portable Executable Injection
is related to Verclsid
is related to Compromise Accounts
is related to Launchctl
is related to Botnet
is related to Network Device CLI
is related to Shell History
is related to XPC Services
is related to Virtualization/Sandbox Evasion
is related to Web Service
is related to Credentials In Files
is related to DNS Calculation
is related to Mshta
is related to Login Items
is related to Stage Capabilities
is related to Link Target
is related to Multi-Stage Channels
is related to Financial Theft
is related to Execution Guardrails
is related to Cloud Storage Object Discovery
is related to Web Cookies
is related to Log Enumeration
is related to Token Impersonation/Theft
is related to Exfiltration to Code Repository
is related to Cloud Services
is related to Port Knocking
is related to LNK Icon Smuggling
is related to Web Services
is related to Steal Application Access Token
is related to Spearphishing Attachment
is related to Additional Cloud Credentials
is related to User Execution
is related to Internal Defacement
is related to Hidden Users
is related to Make and Impersonate Token
is related to Group Policy Preferences
is related to Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
is related to Cloud Account
is related to Audio-Visual Content
is related to Process Discovery
is related to Launchd
is related to Network Provider DLL
is related to Windows Management Instrumentation Event Subscription
is related to CDNs
is related to User Activity Based Checks
is related to Cloud Service Hijacking
is related to Cloud Accounts
is related to Software Deployment Tools
is related to Exfiltration Over C2 Channel
is related to Parent PID Spoofing
is related to Gather Victim Org Information
is related to Forge Web Credentials
is related to Multi-Factor Authentication Request Generation
is related to Compromise Host Software Binary
is related to Chat Messages
is related to PowerShell
is related to Change Default File Association
is related to VDSO Hijacking
is related to Multiband Communication
is related to File Transfer Protocols
is related to Selective Exclusion
is related to Exploitation for Credential Access
is related to Emond
is related to One-Way Communication
is related to Gather Victim Network Information
is related to Exploitation of Remote Services
is related to Internal Spearphishing
is related to Services File Permissions Weakness
is related to Registry Run Keys / Startup Folder
is related to Trusted Relationship
is related to Cloud Account
is related to Local Groups
is related to LC_MAIN Hijacking
is related to Search Open Websites/Domains
is related to Account Manipulation
is related to Exfiltration Over Alternative Protocol
is related to Kernel Modules and Extensions
is related to Delay Execution
is related to GUI Input Capture
is related to Network Device Firewall
is related to Tool
is related to Exfiltration over USB
is related to KernelCallbackTable
is related to Search Closed Sources
is related to Systemd Timers
is related to Phishing
is related to Graphical User Interface
is related to ROMMONkit
is related to Compiled HTML File
is related to Compute Hijacking
is related to Network Share Connection Removal
is related to Multi-hop Proxy
is related to Brute Force
is related to Unix Shell
is related to Outlook Forms
is related to Remote Access Hardware
is related to Data Manipulation
is related to Inter-Process Communication
is related to Data Obfuscation
is related to Data from Network Shared Drive
is related to Web Services
is related to Modify System Image
is related to Hijack Execution Flow
is related to Browser Fingerprint
is related to Lua
is related to Indicator Removal from Tools
is related to Malicious Image
is related to Container Service
is related to Valid Accounts
is related to Non-Standard Port
is related to Social Media Accounts
is related to Process Hollowing
is related to Exploitation for Privilege Escalation
is related to Resource Forking
is related to Account Access Removal
is related to Credential Stuffing
is related to Obfuscated Files or Information
is related to Multi-Factor Authentication
is related to Remote Email Collection
is related to IIS Components
is related to Invalid Code Signature
is related to Generate Content
is related to Run Virtual Instance
is related to Polymorphic Code
is related to Password Policy Discovery
is related to Event Triggered Execution
is related to Unix Shell Configuration Modification
is related to Forced Authentication
is related to SID-History Injection
is related to Network Boundary Bridging
is related to Data Encrypted for Impact
is related to Prevent Command History Logging
is related to Subvert Trust Controls
is related to Elevated Execution with Prompt
is related to Firmware
is related to Encrypted Channel
is related to Authentication Package
is related to Regsvr32
is related to Exfiltration to Text Storage Sites
is related to Software
is related to Input Capture
is related to Spearphishing Voice
is related to Exploits
is related to Disable or Modify Tools
is related to Social Media
is related to Customer Relationship Management Software
is related to Component Object Model Hijacking
is related to Credentials
is related to Compromise Software Supply Chain
is related to Rename Legitimate Utilities
is related to Bidirectional Communication
is related to Exploitation for Client Execution
is related to Wordlist Scanning
is related to Email Bombing
is related to Outlook Home Page
is related to Asymmetric Cryptography
is related to Exfiltration to Cloud Storage
is related to Lateral Tool Transfer
is related to Path Interception by Unquoted Path
is related to Install Digital Certificate
is related to Startup Items
is related to System Language Discovery
is related to Non-Application Layer Protocol
is related to Container CLI/API
is related to Steganography
is related to DNS Server
is related to Cloud Application Integration
is related to Protocol or Service Impersonation
is related to Query Registry
is related to Data Transfer Size Limits
is related to Web Session Cookie
is related to Domain Accounts
is related to Regsvcs/Regasm
is related to Path Interception
is related to Python Startup Hooks
is related to Install Root Certificate
is related to Network Logon Script
is related to Endpoint Denial of Service
is related to Compile After Delivery
is related to Safe Mode Boot
is related to System Location Discovery
is related to VBA Stomping
is related to BITS Jobs
is related to MSBuild
is related to Modify Cloud Compute Configurations
is related to Domain Fronting
is related to ARP Cache Poisoning
is related to Security Software Discovery
is related to Hidden Window
is related to ClickOnce
is related to Python
is related to Relocate Malware
is related to Identify Roles
is related to Data Encoding
is related to AppInit DLLs
is related to Phishing for Information
is related to Resource Hijacking
is related to Impersonation
is related to Establish Accounts
is related to Obtain Capabilities
is related to Screensaver
is related to Conditional Access Policies
is related to Create Cloud Instance
is related to Cloud Secrets Management Stores
is related to Code Repositories
is related to Transmitted Data Manipulation
is related to /etc/passwd and /etc/shadow
is related to Launch Agent
is related to System Services
is related to Windows Command Shell
is related to Proc Memory
is related to Acquire Access
is related to Patch System Image
is related to Silver Ticket
is related to Data from Information Repositories
is related to Clear Persistence
is related to Hypervisor CLI
is related to Windows Credential Manager
is related to Masquerade Account Name
is related to Hardware Additions
is related to Remote Desktop Software
is related to Server Software Component
is related to Data Destruction
is related to Non-Standard Encoding
is related to Domain Controller Authentication
is related to Transfer Data to Cloud Account
is related to HTML Smuggling
is related to Reversible Encryption
is related to Command Obfuscation
is related to File Deletion
is related to Drive-by Compromise
is related to Network Denial of Service
is related to Cloud Administration Command
is related to Installer Packages
is related to Scanning IP Blocks
is related to Template Injection
is related to RC Scripts
is related to Access Token Manipulation
is related to Multi-Factor Authentication Interception
is related to Software Packing
is related to Serverless
is related to Web Protocols
is related to Visual Basic
is related to Hidden File System
is related to Systemd Service
is related to Exclusive Control
is related to RDP Hijacking
is related to Create Account
is related to XDG Autostart Entries
is related to Server
is related to Cloud Service Discovery
is related to Malicious Copy and Paste
is related to Remote System Discovery
is related to Network Service Discovery
is related to Domain Properties
is related to Software Discovery
is related to Cloud Service Dashboard
is related to Thread Local Storage
is related to Debugger Evasion
is related to Space after Filename
is related to Re-opened Applications
is related to SEO Poisoning
is related to Pass the Hash
is related to Exfiltration Over Physical Medium
is related to Ingress Tool Transfer
is related to SyncAppvPublishingServer
is related to Additional Email Delegate Permissions
is related to Code Signing Certificates
is related to Serverless Execution
is related to TCC Manipulation
is related to Invisible Unicode
is related to Ptrace System Calls
is related to Power Settings
is related to Dynamic API Resolution
is related to Remote Desktop Protocol
is related to Logon Script (Windows)
is related to ListPlanting
is related to Hide Infrastructure
is related to Domain or Tenant Policy Modification
is related to XSL Script Processing
is related to Scan Databases
is related to Hidden Files and Directories
is related to Create Snapshot
is related to Determine Physical Locations
is related to Office Test
is related to Develop Capabilities
is related to NTDS
is related to Cloud Firewall
is related to SNMP (MIB Dump)
is related to Disable or Modify System Firewall
is related to Steganography
is related to Malicious Link
is related to Application Access Token
is related to LSASS Driver
is related to Service Execution
is related to Cloud Accounts
is related to Environmental Keying
is related to Fallback Channels
is related to Local Storage Discovery
is related to NTFS File Attributes
is related to Kerberoasting
is related to DCSync
is related to System Time Discovery
is related to At
is related to Dynamic-link Library Injection
is related to Exploits
is related to Modify Authentication Process
is related to Udev Rules
is related to Credential API Hooking
is related to Firmware Corruption
is related to Inhibit System Recovery
is related to Netsh Helper DLL
is related to Spearphishing via Service
is related to Internal Proxy
is related to System Script Proxy Execution
is related to Dead Drop Resolver
is related to Junk Data
is related to Spearphishing Service
is related to Commonly Used Port
is related to vSphere Installation Bundles
is related to Container API
is related to Domains
is related to SQL Stored Procedures
is related to Network Device Authentication
is related to Disk Content Wipe
is related to Messaging Applications
is related to Exfiltration Over Unencrypted Non-C2 Protocol
is related to Compression
is related to Dylib Hijacking
is related to Downgrade System Image
is related to Email Spoofing
is related to Local Accounts
is related to Wi-Fi Networks
is related to Exploitation for Stealth
is related to Trusted Developer Utilities Proxy Execution
is related to System Shutdown/Reboot
is related to MMC
is related to Process Argument Spoofing
is related to COR_PROFILER
Impressum Deutsch Englisch